Dental Office

Most IT directors don’t start thinking about ITAD vendors until something happens that will require them to take action. A lease expires. A data center refresh gets approved. A compliance officer sends an email with too many question marks in it. Whatever the cause, the selection process that follows tends to get compressed — and that compression is where organizations make decisions they regret later.

I’ve been in this industry for twenty years. I walked the data center floors at 2:00 am before a Monday morning cutover. I’ve reviewed chain-of-custody records that were missing two-thirds of what they were supposed to contain. I’ve seen the Certificate of Recycling handed to a compliance team that needed a Certificate of Destruction and watched the realization slowly dawn on everyone in the room. The checklist below exists because of situations exactly like those.

Gladly, MARRS Recycling has worked through these exact scenarios with healthcare systems, financial institutions, and enterprise IT teams, and the patterns repeat. Good vendors look a certain way. If you don’t want to be left out, here’s what you need to know when selecting an ITAD vendor.

First, Get Clear on What You’re Actually Buying

ITAD (IT Asset Disposition) and eWaste recycling overlap, but treating them as the same thing causes real problems. Remember that ITAD is the managed process of retiring IT assets. These include data sanitization, value recovery, remarketing, and responsible end-of-life handling. On the other hand, recycling is what happens to assets that have no remaining resale value. A competent vendor handles both tracks and tells you upfront which track each asset belongs on.

The liability question is what makes vendor selection genuinely important, not just administratively necessary. Third-party vendor compromise ranked as the second most costly attack vector in IBM’s 2025 X-Force threat data, averaging $4.91 million per incident. The hardware leaving your facility still holds data. The chain between your loading dock and final disposition is your legal exposure. An uncertified vendor with no documented process doesn’t save you money, it only shifts risk onto you.

“I’ve reviewed ITAD programs at organizations of every size. The ones with real exposure aren’t the ones that skipped encryption on their servers. They’re the ones that handed a pallet of drives to a vendor and never asked what happened next.” — Matt Self, ITAD Consultant

The Checklist

 

1. Verify Certifications — By Name, Not Vague Assurance

“We’re certified” is not enough. Certifications expire. They get suspended. Occasionally, vendors misrepresent them, not always intentionally.

The current standard for responsible electronics recycling is R2v3 — the third version of the Responsible Recycling Standard. It covers environmental management, data security controls, worker health and safety, and critically, it requires audited downstream vendor accountability. That last part matters more than most buyers realize.

Other credentials worth verifying:

  • NAID AAA: specific to secure data destruction operations
  • ISO 14001: environmental management system
  • ISO 27001: information security management
  • e-Stewards: an alternative to R2v3 with stricter controls on export destinations

One thing buyers miss: R2v3 Appendix C (Test and Repair) is a separate qualification that signals a vendor can properly assess, refurbish, and remarket equipment. If value recovery matters to you, ask whether they hold this specifically.

It is important to verify everything directly. Most certifying bodies have public lookup tools. Takes five minutes and tells you more than any vendor sales deck.

2. Ask Exactly How They Handle Data Destruction — By Media Type

This is the question that separates vendors who know what they’re doing from vendors who’ve memorized the right vocabulary. Vagueness here is the tell.

NIST SP 800-88 Rev. 1 is the governing federal guideline for media sanitization. It defines three approaches: Clear (logical overwrite), Purge (cryptographic erase, degaussing), and Destroy (physical shredding or disintegration). The right method depends on the media type and the sensitivity classification of what it holds.

Some specifics that matter in practice:

  • Magnetic HDDs can be degaussed or overwritten, but degaussing renders the drive non-functional — which is fine if destruction is the goal, but rules out resale
  • SSDs and NVMe drives do not respond reliably to degaussing — for these, cryptographic erase or physical shredding is required
  • Optical media and legacy tape require physical destruction regardless

Some clients still reference DoD 5220.22-M in their contracts. That standard has been largely superseded by NIST 800-88 for most use cases. If a vendor cites it as their primary framework without acknowledging the current standard, that’s a sign they haven’t kept pace.

Ask these questions specifically: “What method do you apply to SSDs, and what does the documentation look like at the asset level?” A vendor who knows their process will answer without hesitation. If one cannot answer these questions properly, then they are not a right fit.

3. Require Serialized Chain-of-Custody Documentation

Chain of custody is your legal protection if a breach investigation ever traces back to decommissioned hardware. It is not a formality.

A properly structured chain of custody follows individual assets, not pallets, not batch lots, not weight tickets, from your facility through intake, sanitization, and final disposition. Every transfer gets documented. Every handler is identified. The terminal document in that chain is a Certificate of Destruction (CoD): it lists the asset serial number, the destruction method applied, the date and location, and is signed by an accountable custodian.

Know the difference between a CoD and a Certificate of Recycling. A Certificate of Recycling confirms material was processed and diverted from landfill. It says nothing about data destruction. For regulated industries — healthcare under HIPAA, financial services under GLBA — the CoD is the document your compliance team actually needs. Audit prep meetings where an entire device refresh had only batch recycling receipts, no serial numbers, no destruction confirmation, are not uncommon. That’s a gap you can’t close retroactively.

4. Push on Downstream Vendor Accountability

Your liability doesn’t stop when assets leave your facility. It extends through the entire downstream chain — every subcontractor, every secondary recycler, every export destination. R2v3 requires vendors to conduct and document audits of their downstream partners. Ask for evidence that this actually happens.

Where does the material go? That’s a direct question worth asking directly. Qualified vendors can tell you the names of their smelters, their certified refurbishers, their recycling partners. Vendors who get evasive about this are telling you something important: they don’t know, or they know and don’t want to say.

5. Confirm Insurance Coverage — Specifically

Ask for the following:

  • Cyber liability insurance
  • Pollution liability (required for meaningful R2v3 compliance)
  • Commercial general liability
  • Errors and omissions coverage

A vendor who deflects this question or produces a vague summary without coverage limits is one who may not have adequate coverage. If something goes wrong — a data exposure, an environmental violation — you want a financially capable partner, not an apology.

6. Understand How Value Recovery Actually Works

Properly managed ITAD can offset its own cost. Enterprise servers, recent-generation laptops, network switching equipment, and mobile devices frequently carry meaningful secondary market value. A good vendor audits assets before disposition, gives you a realistic estimate upfront, and documents settlement proceeds transparently.

Be skeptical of vendors who quote specific recovery figures before they’ve seen the equipment. Markets shift. Condition grades vary. The right answer is a realistic range based on current secondary market data, not a number designed to win the contract.

7. For Decommissioning Projects, Test Their Project Management

If you’re retiring a data center or managing a large-scale device refresh, this becomes an operational question as much as a compliance one. Sequencing matters: power-down schedules, physical removal, secure transport, processing timelines, and final reporting all have to coordinate without disrupting active systems.

Ask how they handle multi-site logistics. Ask what their escalation process looks like when something goes sideways — because on large decommissioning projects, something always does. A vendor with real experience will have a direct, specific answer. One without it will give you reassurance and not much substance.

8. Reference Check the Right Way

Don’t just ask for references. Ask for clients in your industry, with similar asset volumes, dealing with similar regulatory requirements. Healthcare and manufacturing have different compliance obligations, and experience in one doesn’t transfer automatically.

Also look at how long the vendor has been operating. An ITAD company that’s been around less than five years hasn’t necessarily weathered regulatory changes, market cycles, or the complex projects that reveal process gaps. Financial instability in a vendor is an underappreciated risk — organizations under financial pressure cut corners in the places you can’t see until it’s too late.

OU Daily Covers Norman eWaste Event Featuring MARRS Recycling

A Quick Reference Table

Question to Ask What You’re Actually Testing
Which certifications do you hold — and can I verify them? Transparency and compliance baseline
What destruction method do you use for SSDs specifically? Technical competence
Can you provide a serialized Certificate of Destruction per asset? Chain-of-custody quality
Who are your downstream vendors and how are they audited? Downstream liability management
What insurance policies do you carry? Financial accountability
Have you managed decommissioning projects similar to ours? Operational capability

How MARRS Recycling Can Help

If you’re in the middle of vendor evaluation, approaching a decommissioning project, or trying to close a documentation gap in an existing program, MARRS Recycling is worth a direct conversation. They handle R2v3-compliant ITAD, data center decommissioning, and hard drive destruction with serialized chain-of-custody reporting — asset level, not batch level. Their downstream vendor relationships are audited, and their team can walk you through exactly what happens to each asset class from pickup to final disposition.

Call MARRS Recycling at (866) 884-0266.

What Our Clients Are Saying

“The staff has always been helpful, even going so far as to give me a tour my first time there. They do great work for the community and keep a tidy shop.”

— Robert S. Hastings IV

“Working with MARRS Recycling center was great. We are a small company and had several old desktop printers. They worked fast and helped us get rescheduled. The pickup team was very friendly too. I would highly recommend them.”

— David Miller